Rebranded product names and fixed g errors

This commit is contained in:
Dulce Montemayor
2019-07-25 09:37:06 -07:00
committed by GitHub
parent 0035f23705
commit 79147e5004

View File

@ -27,7 +27,7 @@ ms.topic: conceptual
Each security control lists recommendations that you can take to increase the security posture of your organization. Each security control lists recommendations that you can take to increase the security posture of your organization.
### Endpoint detection and response (EDR) optimization ### Endpoint detection and response (EDR) optimization
For an machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for your Endpoint detection and response tool. For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for your Endpoint detection and response tool.
>[!IMPORTANT] >[!IMPORTANT]
>This feature is available for machines on Windows 10, version 1607 or later. >This feature is available for machines on Windows 10, version 1607 or later.
@ -45,18 +45,18 @@ You can take the following actions to increase the overall security score of you
For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md).
### Windows Defender Antivirus (Windows Defender AV) optimization ### Microsoft Defender Antivirus (Microsoft Defender AV) optimization
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender AV is fulfilled. For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Microsoft Defender AV is fulfilled.
>[!IMPORTANT] >[!IMPORTANT]
>This feature is available for machines on Windows 10, version 1607 or later. >This feature is available for machines on Windows 10, version 1607 or later.
#### Minimum baseline configuration setting for Windows Defender AV: #### Minimum baseline configuration setting for Microsoft Defender AV:
Machines are considered "well configured" for Windows Defender AV if the following requirements are met: Machines are considered "well configured" for Microsoft Defender AV if the following requirements are met:
- Windows Defender AV is reporting correctly - Microsoft Defender AV is reporting correctly
- Windows Defender AV is turned on - Microsoft Defender AV is turned on
- Security intelligence is up to date - Security intelligence is up-to-date
- Real-time protection is on - Real-time protection is on
- Potentially Unwanted Application (PUA) protection is enabled - Potentially Unwanted Application (PUA) protection is enabled
@ -64,16 +64,16 @@ Machines are considered "well configured" for Windows Defender AV if the followi
You can take the following actions to increase the overall security score of your organization: You can take the following actions to increase the overall security score of your organization:
>[!NOTE] >[!NOTE]
> For the Windows Defender Antivirus properties to show, you'll need to ensure that the Windows Defender Antivirus Cloud-based protection is properly configured on the machine. > For the Microsoft Defender Antivirus properties to show, you'll need to ensure that the Microsoft Defender Antivirus Cloud-based protection is properly configured on the machine.
- Fix antivirus reporting - Fix antivirus reporting
- This recommendation is displayed when the Windows Defender Antivirus is not properly configured to report its health state. For more information on fixing the reporting, see [Configure and validate network connections](../windows-defender-antivirus/configure-network-connections-windows-defender-antivirus.md). - This recommendation is displayed when the Microsoft Defender Antivirus is not properly configured to report its health state. For more information on fixing the reporting, see [Configure and validate network connections](../windows-defender-antivirus/configure-network-connections-windows-defender-antivirus.md).
- Turn on antivirus - Turn on antivirus
- Update antivirus Security intelligence - Update antivirus Security intelligence
- Turn on real-time protection - Turn on real-time protection
- Turn on PUA protection - Turn on PUA protection
For more information, see [Configure Windows Defender Antivirus](../windows-defender-antivirus/configure-windows-defender-antivirus-features.md). For more information, see [Configure Microsoft Defender Antivirus](../windows-defender-antivirus/configure-windows-defender-antivirus-features.md).
### OS security updates optimization ### OS security updates optimization
@ -90,15 +90,15 @@ You can take the following actions to increase the overall security score of you
For more information, see [Windows Update Troubleshooter](https://support.microsoft.com/help/4027322/windows-windows-update-troubleshooter). For more information, see [Windows Update Troubleshooter](https://support.microsoft.com/help/4027322/windows-windows-update-troubleshooter).
### Windows Defender Exploit Guard (Windows Defender EG) optimization ### Microsoft Defender Exploit Guard (Microsoft Defender EG) optimization
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on machines so that the minimum baseline configuration setting for Windows Defender EG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Windows Defender EG events on the Microsoft Defender ATP Machine timeline. For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on machines so that the minimum baseline configuration setting for Microsoft Defender EG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Microsoft Defender EG events on the Microsoft Defender ATP Machine timeline.
>[!IMPORTANT] >[!IMPORTANT]
>This security control is only applicable for machines with Windows 10, version 1709 or later. >This security control is only applicable for machines with Windows 10, version 1709 or later.
#### Minimum baseline configuration setting for Windows Defender EG: #### Minimum baseline configuration setting for Microsoft Defender EG:
Machines are considered "well configured" for Windows Defender EG if the following requirements are met: Machines are considered "well configured" for Microsoft Defender EG if the following requirements are met:
- System level protection settings are configured correctly - System level protection settings are configured correctly
- Attack Surface Reduction rules are configured correctly - Attack Surface Reduction rules are configured correctly
@ -148,21 +148,21 @@ You can take the following actions to increase the overall security score of you
- Turn on all system-level Exploit Protection settings - Turn on all system-level Exploit Protection settings
- Set all ASR rules to enabled or audit mode - Set all ASR rules to enabled or audit mode
- Turn on Controlled Folder Access - Turn on Controlled Folder Access
- Turn on Windows Defender Antivirus on compatible machines - Turn on Microsoft Defender Antivirus on compatible machines
For more information, see [Windows Defender Exploit Guard](../windows-defender-exploit-guard/windows-defender-exploit-guard.md). For more information, see [Microsoft Defender Exploit Guard](../windows-defender-exploit-guard/windows-defender-exploit-guard.md).
### Windows Defender Application Guard (Windows Defender AG) optimization ### Microsoft Defender Application Guard (Microsoft Defender AG) optimization
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender AG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Windows Defender AG events on the Microsoft Defender ATP Machine timeline. For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Microsoft Defender AG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Microsoft Defender AG events on the Microsoft Defender ATP Machine timeline.
>[!IMPORTANT] >[!IMPORTANT]
>This security control is only applicable for machines with Windows 10, version 1709 or later. >This security control is only applicable for machines with Windows 10, version 1709 or later.
#### Minimum baseline configuration setting for Windows Defender AG: #### Minimum baseline configuration setting for Microsoft Defender AG:
Machines are considered "well configured" for Windows Defender AG if the following requirements are met: Machines are considered "well configured" for Microsoft Defender AG if the following requirements are met:
- Hardware and software prerequisites are met - Hardware and software prerequisites are met
- Windows Defender AG is turned on compatible machines - Microsoft Defender AG is turned on compatible machines
- Managed mode is turned on - Managed mode is turned on
##### Recommended actions: ##### Recommended actions:
@ -170,26 +170,26 @@ You can take the following actions to increase the overall security score of you
- Ensure hardware and software prerequisites are met - Ensure hardware and software prerequisites are met
>[!NOTE] >[!NOTE]
>This improvement item does not contribute to the security score in itself because it's not a prerequisite for Windows Defender AG. It gives an indication of a potential reason why Windows Defender AG is not turned on. >This improvement item does not contribute to the security score in itself because it's not a prerequisite for Microsoft Defender AG. It gives an indication of a potential reason why Microsoft Defender AG is not turned on.
- Turn on Windows Defender AG on compatible machines - Turn on Microsoft Defender AG on compatible machines
- Turn on managed mode - Turn on managed mode
For more information, see [Windows Defender Application Guard overview](../windows-defender-application-guard/wd-app-guard-overview.md). For more information, see [Microsoft Defender Application Guard overview](../windows-defender-application-guard/wd-app-guard-overview.md).
### Windows Defender SmartScreen optimization ### Microsoft Defender SmartScreen optimization
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender SmartScreen is fulfilled. For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Microsoft Defender SmartScreen is fulfilled.
>[!WARNING] >[!WARNING]
> Data collected by Windows Defender SmartScreen might be stored and processed outside of the storage location you have selected for your Microsoft Defender ATP data. > Data collected by Microsoft Defender SmartScreen might be stored and processed outside of the storage location you have selected for your Microsoft Defender ATP data.
>[!IMPORTANT] >[!IMPORTANT]
>This security control is only applicable for machines with Windows 10, version 1709 or later. >This security control is only applicable for machines with Windows 10, version 1709 or later.
#### Minimum baseline configuration setting for Windows Defender SmartScreen: #### Minimum baseline configuration setting for Microsoft Defender SmartScreen:
The following settings must be configured with the following settings: The following settings must be configured with the following settings:
- Check apps and files: **Warn** or **Block** - Check apps and files: **Warn** or **Block**
- SmartScreen for Microsoft Edge: **Warn** or **Block** - SmartScreen for Microsoft Edge: **Warn** or **Block**
@ -201,27 +201,27 @@ You can take the following actions to increase the overall security score of you
- Set **SmartScreen for Microsoft Edge** to **Warn** or **Block** - Set **SmartScreen for Microsoft Edge** to **Warn** or **Block**
- Set **SmartScreen for Microsoft store apps** to **Warn** or **Off** - Set **SmartScreen for Microsoft store apps** to **Warn** or **Off**
For more information, see [Windows Defender SmartScreen](../windows-defender-smartscreen/windows-defender-smartscreen-overview.md). For more information, see [Microsoft Defender SmartScreen](../windows-defender-smartscreen/windows-defender-smartscreen-overview.md).
### Windows Defender Firewall optimization ### Microsoft Defender Firewall optimization
For a machine to be considered "well configured", Windows Defender Firewall must be turned on and enabled for all profiles and inbound connections are blocked by default. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender Firewall is fulfilled. For a machine to be considered "well configured", Microsoft Defender Firewall must be turned on and enabled for all profiles and inbound connections are blocked by default. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Microsoft Defender Firewall is fulfilled.
>[!IMPORTANT] >[!IMPORTANT]
>This security control is only applicable for machines with Windows 10, version 1709 or later. >This security control is only applicable for machines with Windows 10, version 1709 or later.
#### Minimum baseline configuration setting for Windows Defender Firewall #### Minimum baseline configuration setting for Microsoft Defender Firewall
- Windows Defender Firewall is turned on for all network connections - Microsoft Defender Firewall is turned on for all network connections
- Secure domain profile by enabling Windows Defender Firewall and ensure that Inbound connections is set to Blocked - Secure domain profile by enabling Microsoft Defender Firewall and ensure that Inbound connections are set to Blocked
- Secure private profile by enabling Windows Defender Firewall and ensure that Inbound connections is set to Blocked - Secure private profile by enabling Microsoft Defender Firewall and ensure that Inbound connections are set to Blocked
- Secure public profile is configured by enabling Windows Defender Firewall and ensure that Inbound connections is set to Blocked - Secure public profile is configured by enabling Microsoft Defender Firewall and ensure that Inbound connections are set to Blocked
For more information on Windows Defender Firewall settings, see [Planning settings for a basic firewall policy](https://docs.microsoft.com/windows/security/identity-protection/windows-firewall/planning-settings-for-a-basic-firewall-policy). For more information on Microsoft Defender Firewall settings, see [Planning settings for a basic firewall policy](https://docs.microsoft.com/windows/security/identity-protection/windows-firewall/planning-settings-for-a-basic-firewall-policy).
>[!NOTE] >[!NOTE]
> If Windows Defender Firewall is not your primary firewall, consider excluding it from the security score calculations and make sure that your third-party firewall is configured in a securely. > If Microsoft Defender Firewall is not your primary firewall, consider excluding it from the security score calculations and make sure that your third-party firewall is configured in a securely.
##### Recommended actions: ##### Recommended actions:
@ -234,7 +234,7 @@ You can take the following actions to increase the overall security score of you
- Fix sensor data collection - Fix sensor data collection
- The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md).
For more information, see [Windows Defender Firewall with Advanced Security](https://docs.microsoft.com/windows/security/identity-protection/windows-firewall/windows-firewall-with-advanced-security). For more information, see [Microsoft Defender Firewall with Advanced Security](https://docs.microsoft.com/windows/security/identity-protection/windows-firewall/windows-firewall-with-advanced-security).
### BitLocker optimization ### BitLocker optimization
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for BitLocker is fulfilled. For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for BitLocker is fulfilled.
@ -258,17 +258,17 @@ You can take the following actions to increase the overall security score of you
For more information, see [Bitlocker](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-overview). For more information, see [Bitlocker](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-overview).
### Windows Defender Credential Guard optimization ### Microsoft Defender Credential Guard optimization
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender Credential Guard is fulfilled. For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Microsoft Defender Credential Guard is fulfilled.
>[!IMPORTANT] >[!IMPORTANT]
>This security control is only applicable for machines with Windows 10, version 1709 or later. >This security control is only applicable for machines with Windows 10, version 1709 or later.
#### Minimum baseline configuration setting for Windows Defender Credential Guard: #### Minimum baseline configuration setting for Microsoft Defender Credential Guard:
Machines are considered "well configured" for Windows Defender Credential Guard if the following requirements are met: Machines are considered "well configured" for Microsoft Defender Credential Guard if the following requirements are met:
- Hardware and software prerequisites are met - Hardware and software prerequisites are met
- Windows Defender Credential Guard is turned on compatible machines - Microsoft Defender Credential Guard is turned on compatible machines
##### Recommended actions: ##### Recommended actions:
@ -279,7 +279,7 @@ You can take the following actions to increase the overall security score of you
- Fix sensor data collection - Fix sensor data collection
- The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md).
For more information, see [Manage Windows Defender Credential Guard](https://docs.microsoft.com/windows/security/identity-protection/credential-guard/credential-guard-manage). For more information, see [Manage Microsoft Defender Credential Guard](https://docs.microsoft.com/windows/security/identity-protection/credential-guard/credential-guard-manage).
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-sadashboard-belowfoldlink) >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-sadashboard-belowfoldlink)